Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.7% | 💥 PoC | Apache Jspwiki | 20/5/2019 | 17/6/2026 | A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. | |
| Modificada | Alta (7.5) | 10.0% | 💥 PoC | Apache Jspwiki | 28/3/2019 | 17/6/2026 | A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details. | |
| Modificada | Media (6.1) | 5.1% | — | Apache Jspwiki | 28/3/2019 | 17/6/2026 | In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser. | |
| Modificada | Media (6.1) | 5.4% | — | Apache Jspwiki | 11/2/2019 | 17/6/2026 | A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking. | |
| Modificada | Alta (9.3) | 4.4% | 💥 Exploit | Jspwiki | 10/3/2008 | 16/6/2026 | Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page." | |
| Modificada | Alta (9.3) | 7.6% | 💥 Exploit | Jspwiki | 10/3/2008 | 16/6/2026 | Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Jspwiki | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b. | |
| Modificada | Media (4.3) | 1.4% | — | Jspwiki | 27/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to wiki-3/Login.jsp and unspecified other components. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Jspwiki | 27/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) members parameters in (a) NewGroup.jsp; the (3) edittime parameter in (b) Edit.jsp; the (4) edittime, (5) author, and (6) link parameters in… | |
| Modificada | Media (4.3) | 1.3% | — | Jspwiki | 27/9/2007 | 16/6/2026 | JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/. | |
| Modificada | Media (4.3) | 1.3% | — | Jspwiki | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter. |